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IN THE CLAIMS : 

Pending claims follow. 

1 . (Previously Amended) A method for on-access computer virus scanning of 
files in an efficient manner, comprising the steps of: 

(a) identifying a process for accessing files and selecting virus detection actions 
based at least in part on the identified process if no identifier is assigned 
thereto; 

(b) assigning an identifier to the process if no identifier is assigned thereto; 

(c) selecting virus detection actions based at least in part on the identifier if 
existent; and 

(d) performing the virus detection actions on the files; 

(e) wherein the process is associated with an application program, and different 
identifiers are assigned to different application programs so that the virus 
detection actions are tailored for the processes associated with the 
application programs. 

2. (Original) The method as recited in claim h wherein the identifier is cleared 
upon the occurrence of a predetermined event. 

3. (Original) The method as recited in claim 2, wherein the identifier is reused 
after being cleared. 

4. (Original) The method as recited in claim 2, wherein the event is the 
termination of an application. 

5. (Original) The method as recited in claim 4, wherein the identifier is 
assigned by the application, 

6. (Original) The method as recited in claim 4, wherein the application is 
adapted for executing the process. 
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7. (Previously Amended) A computer program product for on-access computer 
virus scanning of files in an efficient manner, comprising; 

(a) computer code for identifying a process for accessing files and selecting 
virus detection actions based at least in part on the identified process if no 
identifier is assigned thereto; 

(b) computer code for assigning an identifier to the process if no identifier is 
assigned thereto; 

(c) computer code for selecting virus detection actions based at least in part on 
the identifier if existent; and 

(d) computer code for perfomiing the virus detection actions on the files; 

(e) wherein the process is associated with an application program, and different 
identifiers are assigned to different application programs so that the virus 
detection actions are tailored for the processes associated with the 
application programs. 

8. (Original) The computer program product as recited in claim 7, wherein the 
identifier is cleared upon the occurrence of a predetermined event. 

9. (Original) The computer program product as recited in claim 8, wherein the 
identifier is reused after being cleared. 

10. (Original) The computer program product as recited in claim 8, wherein the 
event is the termination of an application. 

1 1 . (Original) The computer program product as recited in claim 10, wherein the 
identifier is assigned by the application. 

12. (Original) The computer program product as recited in claim 10, wherein the 
application is adapted for executing the process. 

1 3. (Previously Amended) A system for on-access computer virus scanning of 
files in an eflRcient manner, comprising: 
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(a) logic for identifying a process for accessing files and selecting virus 
detection actions based at least in part on the identified process if no 
identifier is assigned thereco; 

(b) logic for assigning an identifier to the process if no identifier is assigned 
thereto; 

(c) logic for selecting virus detection actions based at least in part on the 
identifier if existent; and 

(d) logic for performing the virus detection actions on the files; 

(e) wherein the process is associated with an application program, and different 
identifiers are assigned to different application programs so that the virus 
detection actions are tailored for the processes associated with the 
application programs. 

14. (Original) The system as recited in claim 1 3, wherein the identifier is cleared 
upon the occurrence of a predetermined event. 

1 5. (Original) The system as recited in claim 14, wherein the identifier is reused 
after being cleared. 

1 6. (Original) The system as recited in claim 14, wherein the event is the 
termination of an application. 

17. (Original) The system as recited In claim 16, wherein the identifier is 
assigned by the application. 

1 8. (Original) The system as recited in claim 16, wherein the application is 
adapted for executing the process. 

19. (Previously Presented) The method as recited in claim I , wherein the virus 
detection actions are selected by determining a category associated with the 
process based on the identifier, and selecting a set of virus detection actions 
based on the determined categor}'. 
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20. (Previously Presented) The method as recited in claim 19, wherein the 

identifier reflects a risk level associated with the application program* and a 
plurality of categories each have virus detection actions tailored for an 
associated risk level. 
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